Solved

Configuration Problems with a Cisco Site-to-Site VPN

Posted on 2009-04-04
1
231 Views
Last Modified: 2012-05-06
I'm trying to add a site-to-site VPN connection to a Cisco 1711 that already has a working EZvpn setup.  I have been over this to the point that I'm just not seeing what I'm missing.  It is failing to establish IKE.  Any pointers as to what I'm missing would be most appreciated.  This is the Hub router config.
20090404-jdn-r01-sanitized.txt
0
Comment
Question by:NelsonS74
1 Comment
 
LVL 9

Accepted Solution

by:
Donboo earned 500 total points
ID: 24067915
You named you static map "dynmap" and gave the reference to your dynamic-map (which you also called dynmap) as first priority whatever static you enter after here dosnt matter as they will match your dynamic map and as the site-to-site dosnt have any groupname to match a ISAKMP will not be established.

crypto map dynmap (Static map name) 1 ipsec-isakmp dynamic dynmap (dynamic map name)

So change your dynamic map to a higher prio like 65000 and add you static as a lower number. that should get you to first base :P

Example of static map with dynamic map:
!
crypto dynamic-map DYN-VPN 1
 set transform-set groupname1
 set isakmp-profile groupname1-profile
 reverse-route
!
crypto dynamic-map DYN-VPN 2
 set transform-set groupname2
 set isakmp-profile groupname2-profile
 reverse-route
!
crypto map VPN 1 ipsec-isakmp
 set peer x.x.x.x
 set transform-set CUST1-L2L
 set pfs group2
 set isakmp-profile CUST1-L2L
 match address CUST1-L2L
!
crypto map VPN 2 ipsec-isakmp
 set peer y.y.y.y
 set transform-set CUST2-L2L
 set pfs group2
 set isakmp-profile CUST2-L2L
 match address CUST2-L2L
!
crypto map VPN 65000 ipsec-isakmp dynamic DYN-VPN
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now